6 ms·
Decrypting Blind's Encrypted API
- jiofih 7y agoIs there any point in encrypting API payloads when the traffic is going via TLS?
- thenewnewguy 7y agoIn theory: no, because anyone able to break the TLS could just slip in some JS to capture your comments. In practice: possibly, because many companies use TLS proxies that probably aren't doing that?
- chocolatkey 7y agoPotentially to prevent MITM proxies on company computers from being able to sniff the traffic. Maybe because of what blind is about, that would make sense? Otherwise, if it's secure TLS, then no reason at all Edit: maybe the reason they use public key for transmission is because you can't reverse that, and that would potentially be where your anonymous complaints your complaints (or whatever you do on blind) would be?
- a1369209993 7y agoNote that as thenewnewguy says, anyone who can MITM your connection can also inject JS spyware (well, more so than usual) to exfiltrate your comments. That's harder (and much harder still to avoid discovery) than just sniffing the traffic, so it might be a useful stopgap, but for real security you need to fix your web browser to reject MITMed connections.
- andersonmvd 7y agoReasons I can think of: depends whether you assume TLS is not going to be broken again and whether the TLS termination happens before the component you want to process the data, to do any sort of check, e.g., web application firewall. With the goal of reducing insider threat and reducing exposure of sensitive data to components that don't need to know such data. However usually it's a bad idea to solely rely on javascript crypto: https://www.nccgroup.trust/us/about-us/newsroom-and-events/blog/2011/august/javascript-cryptography-considered-harmful/ https://www.nccgroup.trust/us/about-us/newsroom-and-events/b...
- jiveturkey 7y agoFor blind? yes. It is designed to be anonymous from your employer. Many employers, especially those for which employees would enjoy anonymous complaining, have TLS-intercepting middleboxes.
- bowmessage 7y agoHow would that work, unless the Blind posters are posting from corp-managed phones which have company-signed certs installed?
- RyJones 7y agolots of places use an MDM profile if you connect to work email, for instance.
- SlowRobotAhead 7y agoThis kind of deep packet inspection is in no way limited to phones.
- bowmessage 7y agosure, my point was really: there's no way for your employer to intercept the packet contents unless they've got their own cert bundle installed, and you'd have to be pretty clueless to use this from a corp machine of any kind.
- techslave 7y agomost people are in fact clueless.
- pheug 7y agoSecurity through obscurity. Pretty sure Blind did this just to piss off scrapers. I mean I've been scraping them for some time until they pulled this encryption trick about a year ago. I didn't have time to reverse engineer their js and keep my scraper up to date, that'd take way more time than it took me to write some 100 lines to scrape them originally. So score 1 for them.
- toast0 7y agoIf your API goes through a CDN you don't fully trust.
- eralps 7y agoNice article! I always wonder what the legal aspects of publishing a reverse engineering article for a private API are? Does the company that the API belongs to have rights to an obligatory take down request?
- userbinator 7y agoIs it really "private" if everyone with a browser and a brain can see what it's doing...?
- eralps 7y agoI also would like to know. Does it even count as intellectual property of the company?
- artificial 7y agoThis is what's frustrating about accessing content online. Is it fair game if it's on a web server since the requester cannot determine intent? Legally it doesn't appear so.
- bowmessage 7y agoI've gone through this same exercise in the past in order to mass-delete a large number of comments on different threads. I was afraid that Blind may one day suffer a data leak. I attempted to reroll the crypto in Ruby, but ultimately failed and went the JS route, same as the author. I also had to roll my own sesion-token refresh logic. Finally I was wondering if any kind of data mining could be done with the tool, but I never took it that far. Thanks for the writeup!
- choppaface 7y agoWell they already had at least one breach: https://techcrunch.com/2018/12/20/blind-anonymous-app-data-exposure/ https://techcrunch.com/2018/12/20/blind-anonymous-app-data-e...
- sonicggg 7y agoYou'd think that engineers from top - tier tech companies would know better, before sharing sensitive information on some random website.
- tehlike 7y agoPeople like venting.
- seangrogg 7y agoOthers don't even care if the info was de-anonymized in the first place and just enjoyed the topics that were more openly discussed there.
- choppaface 7y agoA lot of engineers make money off Blind through referrals, if not through Blind's service ( https://www.rooftopslushie.com/ https://www.rooftopslushie.com/ ) then through private messages.
- kccqzy 7y agoThis is yet another reminder that good JS minification tools exist that can absolutely change object properties into short minimal strings instead of descriptive names. It's called the Closure Compiler in advanced mode. You do have to have quite a bit of discipline in writing the JS to have that though. Some languages like ClojureScript actually do this by default, so it doesn't take much effort. Also it helps if you don't have to use objects (with keys) to transfer data. What I mean is that there's little reason to use { "alias": "b6WJEDTp", "member_nickname": "faRw33", "created_at": "4d", "is_auth": "Y", "board_id": 114961, <snip> when you instead can use a simple array [ "b6WJEDTp", "faRw33", "4d", "Y", 114961, <snip> if you have some post-processing to transform array indices into object keys. Both of these approaches also cut down on the amount of data transferred over the wire, so it saves data and helps speed up the site for users too.
- Pfhreak 7y agoThe thought of the latter just made me shudder. Removing keys locks your API in really unpleasant ways. More importantly, it's less human readable and harder to reason about. Please don't do this unless you've got a very specific need for the performance.
- kccqzy 7y agoKeys are not really removed in code, only from the wire format. In code you can still write `myObject.property` but the minifier translates that to say, `a[6]` instead. Naturally there would be tools for the developer to translate these arrays back into full objects in the case of debugging in production. Harder to reason about yes, but few devs would reason about their code using minified code, why should they reason about using minified wire format? (Of course I must admit that this is only suitable for private APIs, not APIs published to explicitly allow third parties to use.) Have you tried looking at, say, Gmail's XHR requests and responses?
- fastball 7y agoIf you're going to do that, why not just forego human readability entirely and user an interchange format like protobuf or flatbuffers?
- tomsmeding 7y agoSo, they used asymmetric encryption for the request so that a MITM can't read that, but they used symmetric encryption for the response. Though it requires a MITM to fully analyse the code, it allows a MITM to decrypt any response. Cited possible reason (in the conclusion) is performance. I think you don't have to resort to symmetric encryption here, even keeping performance in mind. What you do is generate a new asymmetric keypair on the client for every session, then send the public key over to the server. Then the server encrypts every response with that public key, allowing only the client to decrypt it. Doing that, one can only read a session's network traffic, both ways, if they can read values of variables on the client -- but if one can do that, you can read everything anyway. ;) EDIT: forgot to talk about performance -- you just use a so-called "envelope", where the sending party first encrypts the data symmetrically with a randomly generated key, then encrypts that random key with the asymmetric crypto. The pair (symmetrically encrypted data and the asymmetrically encrypted key) is sent to the receiver, which can use its private key to decrypt the symmetric key, with which it decrypts the data.
- zapttt 7y agothe sad state of web developers. from the silly comments of "infinite scrolling" being definitive proof of a solid rest api behind and that php is or is not capable of either (the writing is too ambiguous). to the roundabout amateur obfuscation (the author calls encryption) that is entirely akin to the JavaScript that disabled right click to "copyright" the page's content in the 90s. sigh
- dirtydroog 7y agoAnd all those medium.com articles they write...
- strictnein 7y agoThe code was mildly obfuscated. The data was encrypted.